Privacy Policy
Last updated: 11 September 2026
This Privacy Policy explains how Kreativdistrikt SRL (“we”, “us”, “our”) collects, uses, and protects your personal data when you use our website or services. It also explains your rights under applicable data protection laws, including the General Data Protection Regulation (GDPR).
For details of the specific cookies used on this website, please see our Cookie Policy.
1. Data Controller
Kreativdistrikt SRL is the Data Controller of your personal data.
Kreativdistrikt SRL Via Petrarca 22 20123 Milan Italy Email: info@kreativdistrikt.com
We operate worldwide, except in embargoed countries.
2. Services
We provide innovation and creative services, including the organisation of hackathons, ideathons, and similar events, both online and offline.
Our website (https://www.kreativdistrikt.com/) provides information about our services and allows users to contact us and book consultations.
No user accounts are required to use our website.
3. Personal Data We Collect
We may collect the following categories of personal data.
3.1 Data provided directly by you
- Name
- Email address
- Phone number
- Company name
- Message content (contact forms or inquiries)
- CVs and application materials (event participation)
- Participant data provided during events
3.2 Event-related data
When you participate in our events, we may also process:
- Attendance records
- Submitted projects or materials
- Event-related communications
- Work produced during events
- Intellectual property-related information relevant to the event terms
3.3 Media data
- Photographs and video recordings taken during events (where applicable)
3.4 Technical data collected automatically
- IP address
- Browser type and version, device type, operating system
- Pages visited, time spent, referring website
- Interaction data such as clicks and scrolling (where you have consented to analytics or marketing cookies)
4. How We Collect Data
We collect data:
- Directly from you (forms, applications, event participation)
- Automatically via website analytics and security tools
- Through third-party event platforms used to manage events
We use third-party platforms such as HackSquad (or equivalent event management systems) to facilitate event participation and operations.
5. Legal Basis for Processing
We process personal data in accordance with the legal bases provided under Article 6 of the GDPR. Depending on the specific context, the legal bases include:
Performance of a contract (Art. 6(1)(b) GDPR) When processing is necessary for the performance of a contract with you or to take steps before entering into a contract. This includes managing event participation, delivering services, and processing related requests.
Consent (Art. 6(1)(a) GDPR) When you have given clear consent for us to process your personal data for specific purposes, such as the use of photographs or video recordings for promotional purposes, or the use of non-essential cookies and similar tracking technologies.
Legitimate interests (Art. 6(1)(f) GDPR) When processing is necessary for our legitimate interests, provided that such interests are not overridden by your fundamental rights and freedoms. This includes website security, prevention of fraud or misuse, and service improvement.
Legal obligation (Art. 6(1)(c) GDPR) When processing is necessary to comply with applicable legal obligations, including accounting, tax, and regulatory requirements.
Where processing is based on legitimate interests, you have the right to object to such processing at any time.
6. Use of Personal Data
We use personal data for the following purposes:
- Providing and managing our services
- Organising and administering events
- Processing event applications and participation
- Communicating with users
- Managing inquiries submitted through the website
- Improving our services and operations
- Marketing and promotional activities (where consent applies)
- Documenting events (including photos and videos, where applicable)
- Managing business relationships and contracts
- Protecting the security and integrity of our website
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, and in accordance with applicable legal and contractual obligations.
| Category of data | Retention period |
|---|---|
| Contact form submissions and inquiries | 24 months from last contact |
| Event participant data | Duration of the event plus 24 months |
| CVs and application materials | 12 months from the end of the selection process |
| Accounting and invoicing records | 10 years, as required by Art. 2220 of the Italian Civil Code |
| Analytics data | 14 months |
| Security logs, including IP addresses | 6 months |
| Photographs and video recordings | Until consent is withdrawn |
| Cookie consent preferences | 12 months, after which consent is requested again |
Where data is no longer required, it is deleted or irreversibly anonymised.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate and improve our website.
Cookies are grouped into the following categories:
- Necessary cookies — required for the website to function. These do not require consent.
- Functional cookies — enable features such as appointment booking.
- Statistics cookies — measure website performance and visitor behaviour.
- Marketing cookies — support advertising and audience targeting.
Non-essential cookies are blocked until you give consent through our consent banner. You can change or withdraw your preferences at any time using the “Manage consent” option on any page.
A complete and regularly updated list of the individual cookies used on this website, including their purpose and duration, is available in our Cookie Policy.
9. Third-Party Services
We use third-party service providers to support the operation of our website and the organisation of our services and events. These third parties may process personal data on our behalf, or in some cases as independent data controllers.
9.1 Analytics and advertising
| Service | Provider | Purpose |
|---|---|---|
| Google Analytics 4 | Google Ireland Ltd | Website usage measurement |
| Google Tag Manager | Google Ireland Ltd | Management of tracking scripts |
| Google Ads | Google Ireland Ltd | Advertising and conversion measurement |
| Meta Pixel and Meta Conversions API | Meta Platforms Ireland Ltd | Advertising, audience targeting, and conversion measurement, including server-side event transmission |
| LinkedIn Insight Tag | LinkedIn Ireland Unlimited Company | Advertising and conversion measurement |
| Hotjar | Hotjar Ltd (Malta) | Behaviour analytics, including heatmaps and session recordings |
9.2 Website functionality
| Service | Provider | Purpose |
|---|---|---|
| Calendly | Calendly LLC (USA) | Appointment scheduling |
| YouTube | Google Ireland Ltd | Embedded video content |
| Google Fonts | Google Ireland Ltd | Website typography |
| Contact Form 7 and Redirection for Contact Form 7 | Self-hosted | Contact form handling; submissions are stored in our website database |
| Email marketing connector (Mailchimp) | Respective provider | Transfer of newsletter sign-ups where you have opted in |
| FluentSMTP | Self-hosted | Transmission of outgoing email |
| WP Rocket and RocketCDN | WP Media SAS (France) | Performance optimisation and content delivery |
| Imagify | WP Media SAS (France) | Image optimisation |
9.3 Security
These services process IP addresses to protect the website against unauthorised access and malicious activity. The legal basis is our legitimate interest in website security (Art. 6(1)(f) GDPR).
| Service | Provider | Purpose |
|---|---|---|
| Wordfence | Defiant Inc (USA) | Firewall, malware scanning, IP logging |
| Really Simple Security | Really Simple Plugins BV (Netherlands) | Website hardening, login protection, IP logging |
| Limit Login Attempts Reloaded | Progress Planner BV | Brute-force protection, IP logging |
9.4 Infrastructure and operations
| Service | Provider | Purpose |
|---|---|---|
| Website hosting | GoDaddy | Hosting and infrastructure |
| Google Workspace | Google Ireland Ltd | Email and internal collaboration |
| HackSquad or equivalent | Respective provider | Event management and participation |
Where these providers act as data processors, they process personal data strictly in accordance with our instructions and applicable data processing agreements. Where they act as independent controllers, their processing is governed by their own privacy policies, which we encourage you to review.
10. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including countries that may not provide the same level of data protection as within the EEA.
This may occur in connection with our use of service providers and platforms such as hosting providers, analytics services, marketing tools, and event management systems.
Where such transfers take place, we ensure that appropriate safeguards are implemented in accordance with the GDPR. These safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Reliance on adequacy decisions issued by the European Commission, including the EU-US Data Privacy Framework where the recipient is certified
- Appropriate technical and organisational security measures
11. CVs, Applications, and Project / Intellectual Property Data
When you apply to participate in our events or submit materials such as CVs, applications, or project-related content, we process your personal data for:
- Evaluating applications and determining eligibility for participation in events
- Managing event organisation and participation
- Facilitating collaboration and execution of event-related activities
- Communicating with participants in relation to the event
CVs and application materials are processed solely for evaluation and selection purposes related to the relevant event.
Project submissions and related materials may be processed in the context of your participation in our events and in accordance with the applicable event terms. This may include information related to intellectual property rights, ownership, or usage of submitted work, as defined in the relevant contractual or event-specific documentation.
Retention periods for this category are set out in Section 7.
12. Photos and Event Media
During the organisation and execution of our events, we may collect and process photographs, video recordings, and similar media content.
This processing is carried out for:
- Documenting our events and activities
- Communicating and reporting on our services
- Promoting our events and organisation through appropriate channels, including our website and social media platforms
Legal basis:
- Consent (Art. 6(1)(a) GDPR) for identifiable photography and video used for promotional purposes
- Legitimate interest (Art. 6(1)(f) GDPR) for general event documentation in which individuals are not the focus of the image
Where processing is based on legitimate interest, you have the right to object to the use of your personal data, including images or recordings, at any time by contacting us at info@kreativdistrikt.com.
We take reasonable measures to ensure that such content is used responsibly and in a manner that respects your privacy. Retention periods are set out in Section 7.
13. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal
To exercise any of these rights, contact us at info@kreativdistrikt.com. We will respond within one month, as required by Art. 12(3) GDPR.
You also have the right to lodge a complaint with the supervisory authority in Italy:
Garante per la Protezione dei Dati Personali Piazza Venezia 11, 00187 Roma www.garanteprivacy.it
14. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encrypted connections (HTTPS), access controls, firewall protection, and monitoring for malicious activity.
However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
15. Children’s Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect or process personal data from minors.
If we become aware that personal data has been collected from an individual under the applicable minimum age without appropriate authorisation, we will take reasonable steps to delete such data promptly.
If parental consent is required under applicable law, we may request verification of such consent before processing any personal data relating to minors.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be published on this page, and the “Last updated” date at the top will be modified accordingly.
17. Contact
For any questions regarding this Privacy Policy, you can contact us at:
Email: info@kreativdistrikt.com
Kreativdistrikt SRL, Via Petrarca 22, 20123 Milan, Italy
